CVE Vulnerabilities

CVE-2012-3022

Published: Apr 16, 2013 | Modified: Apr 16, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.5 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The SaveToFile method in a certain ActiveX control in TrendDisplay.dll in Canary Labs TrendLink 9.0.2.27051 and earlier does not properly restrict the creation of files, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted web site.

Affected Software

Name Vendor Start Version End Version
Trendlink Canarylabs * 9.0.2.27051 (including)

References